Kyoto.なんか #4
զʑ͍͔ʹͯ҆͠શͳ ໊લղܾΛखʹೖΕΔ͔itochanKyoto.* #4
View Slide
ͩΕ•౦ژͷେֶੜ•ͯͳΠϯλʔϯ 2016 ߦͬͯ·ͤΜJUPDIBO!JDIBO
എܠ• ੈؒͰHTTPSԽͷѹ͕ߴ·͍ͬͯΔ• ໊͔͠͠લղܾฏจ• DNSͷ௨৴ܦ࿏Λ҉߸Խ͍ͨ͠ʂʂʂ• ҆શҙࣝͷߴ·Γ
ͦ͜Ͱɺ
DNS over HTTPS (DoH)• HTTPSܦ༝Ͱ໊લղܾ͕Ͱ͖Δ• IETF Draftʹͳ͍ͬͯͯඪ४Խ։࢝• ࣮DNS over TLSͱ͍͏ͷ͋Δ• RFCͰඪ४Խ͞Ε͍ͯΔ (RFC 7858)
✔ ྑ͍ͱ͜Ζ• ໊લղؚܾΊ௨৴Λશʹ҉߸Խ͢Δ͜ͱ͕Մೳʂ• େֶͷճઢͰ҆৺͍ͯ͠ΖΜͳαΠτΛӾཡͰ͖Δ
✘ ѱ͍ͱ͜Ζ• ໊લղܾʹएׯΦʔόʔϔου͕͋ΔʢͱݴΘΕ͍ͯΔʣ• TLS1.3Ͱղܾ͢Δ͔ʁ• ѱ͞Λ͍ͯ͠ΔͱࢥΘΕΔ
DNS over HTTPS ͏ʹ• ͑ͦ͏ͳͱ͜Ζ2ͭ• Google Public DNS: 8.8.8.8, 8.8.4.4• Cloudflare DNS: 1.1.1.1, 1.0.0.1
DNS over HTTPS ͏ʹ• ࣍ͷFirefoxͰCloudflareʹΑΔ DoHͷ͍߹ΘͤΛαϙʔτ͢ΔΒ͍͠• Android PͰOSͰαϙʔτ͢ΔΒ͍͠• ϩʔΧϧʹΫϥΠΞϯτΛཱͯlocalhost:53 ʹ͍߹Θͤ
DNS over HTTPS ͏ʹ• ࣍ͷFirefoxͰCloudflareʹΑΔ DoHͷ͍߹ΘͤΛαϙʔτ͢ΔΒ͍͠• Android PͰOSͰαϙʔτ͢ΔΒ͍͠• ϩʔΧϧʹΫϥΠΞϯτΛཱͯlocalhost:53 ʹ͍߹Θͤˣ͜Ε࠷ߴ
DNS over HTTPS ΫϥΠΞϯτ• Ͳ͔ͬͪೖΕΔ• stubby• cloudflared ←؆୯
͍͖ͬͯ·͠ΐ͏
͜Μͳײ͡
IUUQTUSBOTQBSFODZSFQPSUHPPHMFDPNIUUQTPWFSWJFX